How the scam operates.
この手口は、広く知られたセルフカストディ型のイーサリアム用ウォレットインターフェースの名称と、アジアの大手決済プラットフォームの登録ドメインサフィックスを融合させたドメインを用いて運営されています。この組み合わせは、機関による裏付けがある、あるいは共同ブランドで提供されているサービスであるかのような表面的な印象を作り出すことを目的としています。いずれかの名称を単独で認識している利用者は、両者が組み合わされていることから正当性を推測しかねず、ブランドに関連付けられた管理下のトップレベルドメインが用いられていることで、その印象はさらに強められます。
このような特徴を持つ運営は、一般的にフィッシング基盤として機能します。サイトは見慣れたウォレットインターフェースの複製を表示し、訪問者に対して機密性の高い認証情報、すなわち秘密鍵、シードフレーズ、またはキーストアファイルの入力を促します。その情報がいったん送信されると、運営者は関連するウォレットアドレスに保有されるあらゆる資産に対して、完全かつ取り消し不能なアクセス権を得ます。被害者とのそれ以上のやり取りは不要であり、詐欺は認証情報を取得した時点で完結します。
破綻が明らかになるのは、利用者が正規の経路を通じて自身の保有資産にアクセスしようとして資産が消失していることに気づいたとき、あるいは不正なドメインが完全に名前解決されなくなったときです。その段階では、介入のための猶予はすでに失われているのが通常です。ブロックチェーン上の取引は設計上取り消し不能であり、認証情報の侵害を伴う手口によって移動させられた資産は、取得から数時間のうちに複数のアドレスへ分散されるのが一般的であるため、詳細なオンチェーン分析作業なしに取り戻すことは極めて困難です。
Red flags we documented.
- 01Brand Impersonation via Domain ConstructionThe domain fuses two well-recognised brand identities into a single address, a technique used to manufacture credibility without authorisation from either organisation. Neither brand has affiliated with or endorsed this domain in any documented capacity.
- 02Controlled TLD Exploited as a Trust SignalThe top-level domain used here is associated with a major fintech platform, creating an impression of official endorsement. Operators of fraudulent sites exploit the public assumption that access to restricted, brand-owned domain suffixes implies institutional vetting or partnership.
- 03Confirmed Blacklist EntryThe domain is recorded in the CryptoScamDB blacklist, a community-maintained registry of addresses linked to phishing activity and asset theft. Inclusion reflects reports from affected users or automated threat intelligence pipelines, and constitutes a formal, sourced warning.
- 04Credential-Harvest Attack SurfaceAny wallet interface that solicits private keys or seed phrases represents a categorical risk, regardless of its apparent design quality. Legitimate self-custody wallet software does not transmit these credentials to remote servers under any circumstances.
- 05No Verifiable Operator IdentityNo corporate registration, regulatory licence, or identifiable legal entity is associated with this domain. Operations structured around impersonated brand names are typically designed from the outset to resist attribution and complicate any subsequent enforcement or civil action.
What you can do now.
Open a free 24-hour case assessment with CryptoLeek +
Tell us what happened. A senior analyst reads your file within 24 hours and replies with an honest yes/no/conditional on recovery. The assessment is free. If we cannot recover the funds we say so plainly, including which (free) regulator channel you should use instead. If we accept the case, we open a numbered case file and issue a written quote for a flat investigation retainer before any work begins, scoped to case complexity, the jurisdictions involved, and the on-chain trail.
Trace your funds on-chain with our analysts +
We trace stolen crypto across BTC, ETH, EVM L2s, Solana, Tron, and major stablecoins using the same toolchain as regulators and tier-1 exchange compliance teams. The output is a forensic report anchored to specific transaction hashes and block heights, the evidence that exchanges, payment processors, and counsel actually act on. Recovery starts here.
Recover with counsel where civil action makes sense +
Where the trace lands in a jurisdiction with cooperative banks and courts, we coordinate with bar-licensed counsel in our 40+ jurisdiction network for civil action and asset-freezing orders (Mareva-style). Counsel bill you directly; the CryptoLeek investigation retainer is independent of counsel fees. The outcome is funds released back to your nominated wallet or bank account.